Top Banner
Remote and Branch Networking Fundamentals June 9-14, 2014
36
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Remote & Branch Networking Fundamentals #AirheadsConf Italy

Remote and Branch Networking Fundamentals

June 9-14, 2014

Page 2: Remote & Branch Networking Fundamentals #AirheadsConf Italy

CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved2 #AirheadsConf

Agenda

• Challenges of Deploying Remote networks

• Aruba Solution

• Aruba Instant

• Aruba Instant for Private WAN based Deployments

• Aruba Instant-VPN

• Management and Zero-Touch Deployment

Page 3: Remote & Branch Networking Fundamentals #AirheadsConf Italy

Challenges of Deploying Remote Networks

Page 4: Remote & Branch Networking Fundamentals #AirheadsConf Italy

4CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Who should care?

Branch office / Remote teleworker

Retail

Healthcare

Page 5: Remote & Branch Networking Fundamentals #AirheadsConf Italy

5CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Challenges

Page 6: Remote & Branch Networking Fundamentals #AirheadsConf Italy

Aruba Solution

Page 7: Remote & Branch Networking Fundamentals #AirheadsConf Italy

7CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Aruba Solution

Home Office On The RoadBranch

Datacenter

AirWave Aruba Mobility Controller ClearPass Access Management

Instant-VPN

Mobility Switch

Instant Cluster

Virtual Intranet

Access (VIA) Client

Internet / WAN

Instant Cluster

Page 8: Remote & Branch Networking Fundamentals #AirheadsConf Italy

Management and Zero-Touch Deployment

Page 9: Remote & Branch Networking Fundamentals #AirheadsConf Italy

9CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Internet

Airwave and Aruba Central

Campus Network

Aruba Central Aruba AirWave

Data Center

• Advanced guest services

• Mobile device onboarding

• Unified wired/wireless policy

Airwave

ClearPas

s

Mobility

Switch

Page 10: Remote & Branch Networking Fundamentals #AirheadsConf Italy

10CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Aruba Activate: Zero-touch Deployment

Page 11: Remote & Branch Networking Fundamentals #AirheadsConf Italy

Aruba Instant

Page 12: Remote & Branch Networking Fundamentals #AirheadsConf Italy

12CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Aruba Instant

• Redundancy for internal failure

• Redundancy for external failure

• Organic growth

• Mobility-ready

• RF optimization

• Master AP selection

• Over-the-air provisioning

• WiFi oriented configuration

Simple to deploy

Self-optimizing

Self-healing

Scalable

Page 13: Remote & Branch Networking Fundamentals #AirheadsConf Italy

13CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Aruba Instant Architecture

• Distributed data-plane

– Wireless encryption / decryption, firewall

• Distributed control-plane

– Authentication, DHCP, ARM, WIPS

• Centralized (local) management-plane

– Configuration, firmware management, GUI, SNMP

Page 14: Remote & Branch Networking Fundamentals #AirheadsConf Italy

14CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Automatic RF Management

Infrastructure control

• Automatic RF optimization for coverage & capacity

• Real-time spectrum analysis and interference avoidance

• Load / Application awareness

• Self-healing

Channel 11

Channel 6

Channel 1

Client Control

• Moves clients towards less congested frequency band

• Distributes clients across available spectrum*

• Bandwidth controls

Page 15: Remote & Branch Networking Fundamentals #AirheadsConf Italy

15CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Security tailored for Mobility

Context Aware

On-boarding

Role-based access

Policy Enforcement

• Aruba RFProtect + AirWave RAPIDS• RF Scanning, Rogue AP detection / containment, Valid-station protection

• Encryption• Over-the-air AES encryption, IPSec VPN to datacenter (where applicable)

• Role-based Access• Per-user, per-device access

• Policy Enforcement Firewall• Segregation of business traffic from guest traffic.

• Blacklisting for session violation

• Centralized Monitoring and Alerting

Page 16: Remote & Branch Networking Fundamentals #AirheadsConf Italy

16CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

• No need for separate SSID for QoS.

• Session based DSCP tagging & prioritization

• Multicast-to-unicast conversion for video

• Media-classification for encrypted voice –Apple Facetime

• AirGroup* to manage Apple AirPlay, AirPrint, etc

Mobility Services: Real-time Applications

Clear

Pass

IAP

IAP IAP

Page 17: Remote & Branch Networking Fundamentals #AirheadsConf Italy

17CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Mobility Services: Guest Access

• Securely Manage Visitor Access

– Streamlined workflow; No IT

• Sponsored-based, Visitor Self-Registration, Pre-registration,

Anonymous Guest Access

• 3rd Party Integrations

• APIs for integration with existing applications / CRM tools

– Assignable roles, expiration times, user names, passwords

• Highest Customization

– Skin technology, software plugins, APIs

– Targeted advertising and content delivery

Page 18: Remote & Branch Networking Fundamentals #AirheadsConf Italy

Private WAN based Deployments

Page 19: Remote & Branch Networking Fundamentals #AirheadsConf Italy

19CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Private-WAN based Deployments

Page 20: Remote & Branch Networking Fundamentals #AirheadsConf Italy

20CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Private-WAN based Deployments

Page 21: Remote & Branch Networking Fundamentals #AirheadsConf Italy

21CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Auto-GRE for Guest

Branch office

Datacenter

AirWave ClearPass

Instant Cluster

VRRP Link

Master Standby

Guest Anchor

Master ActiveServers

MPLS

Employee Traffic

Guest Traffic

Page 22: Remote & Branch Networking Fundamentals #AirheadsConf Italy

Aruba Instant-VPN

Page 23: Remote & Branch Networking Fundamentals #AirheadsConf Italy

23CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Datacenter

AirWave/Aruba

Central Aruba Mobility ControllerClearPass solution

Internet / WAN

VRRP Link

Master Standby

DMZ

Master Active

Home Office

Instant

Home office Solution

Home Office

Instant

Page 24: Remote & Branch Networking Fundamentals #AirheadsConf Italy

24CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Branch Office Solution

Branch office

Datacenter

AirWave/Aruba

Central Aruba Mobility ControllerClearPass solution

Instant Cluster

Internet / WAN

VRRP Link

Master Standby

DMZ

Master Active

Branch office

Instant Cluster

Page 25: Remote & Branch Networking Fundamentals #AirheadsConf Italy

25CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

DHCP - How does Distributed L3 work ?

Network 10.0.0.0/8

VLANs 10 to 99

Data Center

Remote Branch

Internet /

WAN

Active

VPN

Tunnel

Client A

Browsing to

Intranet

Browsing to

Youtube

Route on IAP –

For 10.0.0.0/8 network, next

hop is VPN terminating

controller’s IP address

Master IAP Memeber IAP

Client B

Browsing to

Intranet

Browsing to

Youtube

VLAN 250

IAP-VC is the

DHCP Server

DHCP

Request

VC SRC NATs traffic using IAPs local IPVC routes the traffic to the

tunnel

Intranet

Page 26: Remote & Branch Networking Fundamentals #AirheadsConf Italy

26CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

DHCP - How does Centralized L2 work ?

Network 10.0.0.0/8

VLANs 10 to 99

Data Center

Remote Branch

Internet /

WAN

Active

VPN

Tunnel

Client A

Browsing to

Intranet

Browsing to

Youtube

Route on IAP –

For 10.0.0.0/8 network, next

hop is VPN terminating

controller’s IP address

Master IAP Member IAP

Client B

Browsing to

Intranet

Browsing to

Youtube

VLAN 50

DHCP

Request

VC SRC NATs traffic using IAPs local IPVC bridges traffic in the

tunnel

VLAN 50

DHCP Server and

Default Gateway

Intranet

Page 27: Remote & Branch Networking Fundamentals #AirheadsConf Italy

27CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

DHCP - How does Local Subnet work ?

Intranet

Network 10.0.0.0/8

VLANs 10 to 99

Data Center

Remote Branch

Internet /

WAN

Active

VPN

Tunnel

Client A

Browsing to

Intranet

Browsing to

Youtube

Route on IAP –

For 10.0.0.0/8 network, next

hop is VPN terminating

controller’s IP address

Master IAP Slave IAP

Client B

Browsing to

Intranet

Browsing to

Youtube

VLAN 200

IAP-VC is the

DHCP Server

DHCP

Request

VC SRC NATs traffic using IAPs local IPVC SRC NATs traffic using

inner IP

Page 28: Remote & Branch Networking Fundamentals #AirheadsConf Italy

28CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Recommendations

IAP-VPN Modes Usage Recommendations

Distributed L3 Recommended for all deployments.

Local Recommended for Guest networks with centralized captive portal

servers.

Centralized L2 Recommended only if Multicast to branch is a requirement. If

Multicast to branch networks is not required, use L3 modes.

Page 29: Remote & Branch Networking Fundamentals #AirheadsConf Italy

Aruba Instant-VPN Design Options

Page 30: Remote & Branch Networking Fundamentals #AirheadsConf Italy

31CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Single AP deployments

Page 31: Remote & Branch Networking Fundamentals #AirheadsConf Italy

32CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Single AP deployments

Page 32: Remote & Branch Networking Fundamentals #AirheadsConf Italy

33CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Multi-AP deployments

Page 33: Remote & Branch Networking Fundamentals #AirheadsConf Italy

34CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Multi-AP deployments

Page 34: Remote & Branch Networking Fundamentals #AirheadsConf Italy

35CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved

Thank You

#AirheadsConf

Page 35: Remote & Branch Networking Fundamentals #AirheadsConf Italy

41CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Page 36: Remote & Branch Networking Fundamentals #AirheadsConf Italy

42CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved

Thank You

#AirheadsConf